在 8.0.9 之前,Nodemailer 未能对列表(list)字段中的换行符(CR)和换行符(LF)字符进行过滤(sanitized),导致攻击者可以注入任意的邮件消息头。能够控制 参数的攻击者可以通过注入 CRLF 序列,在生成的 RFC 822 消息中添加额外的头部字段,从而改变邮件客户端的行为和消息的语义。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nodemailer | nodemailer | 0 ~ 8.0.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82854 | 9.8 CRITICAL | Nodemailer before 8.0.3 SMTP Command Injection via envelope.size |
| CVE-2026-82659 | 7.1 HIGH | nodemailer before 9.0.1 File Read and SSRF via raw option |
| CVE-2026-82662 | 6.5 MEDIUM | Nodemailer before 8.0.8 TLS Certificate Validation Bypass |
| CVE-2026-82660 | 5.4 MEDIUM | Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess |
| CVE-2024-58379 | 5.3 MEDIUM | nodemailer before 6.9.9 ReDoS via attachDataUrls parameter |
| CVE-2026-82853 | 4.9 MEDIUM | Nodemailer before 8.0.5 SMTP Command Injection via CRLF |
No comments yet